CVE-2024-35845 — Use of Externally-Controlled Format String in Linux
Severity
9.1CRITICALNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.3%
top 49.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateJul 26
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: dbg-tlv: ensure NUL termination
The iwl_fw_ini_debug_info_tlv is used as a string, so we must
ensure the string is terminated correctly before using it.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2
Affected Packages5 packages
▶CVEListV5linux/linuxa9248de42464e546b624e3fc6a8b04b991af3591 — fabe2db7de32a881e437ee69db32e0de785a6209+7
Also affects: Debian Linux 10.0